{"id":1900,"date":"2026-09-03T20:10:04","date_gmt":"2026-09-03T20:10:04","guid":{"rendered":"https:\/\/cybercolombia.co\/index.php\/2026\/09\/03\/ceo-phishing-kits-5k-dropbox-account-hacks-oauth-traps-17-more-stories-cyberdefensa-mx\/"},"modified":"2026-09-03T20:10:04","modified_gmt":"2026-09-03T20:10:04","slug":"ceo-phishing-kits-5k-dropbox-account-hacks-oauth-traps-17-more-stories-cyberdefensa-mx","status":"publish","type":"post","link":"https:\/\/cybercolombia.co\/index.php\/2026\/09\/03\/ceo-phishing-kits-5k-dropbox-account-hacks-oauth-traps-17-more-stories-cyberdefensa-mx\/","title":{"rendered":"CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories \u2013 CYBERDEFENSA.MX"},"content":{"rendered":"<div id=\"articlebody\">\n<p>The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click \u201cAllow.\u201d Why break in when someone might open the door?<\/p>\n<p>That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides that point to unsafe downloads. One wrong letter in a web address can be enough.<\/p>\n<p>There is also ransomware, stolen ID data, hidden attack servers, and weak settings that should have been fixed long ago. Here\u2019s the full list.<\/p>\n<div class=\"article-board\">\n <b\/><\/p>\n<p>The threats change every week. <span data-push-label=\"ThreatsDay Bulletin\" data-push-topic=\"threatsday bulletin:t, recap:i\">Subscribe, and we\u2019ll alert you<\/span> when each new ThreatsDay Bulletin is out.<\/p>\n<\/div>\n<div class=\"td-wrap\">\n<section aria-labelledby=\"threatsday-title\" class=\"td-section\">\n<ol class=\"td-timeline\" role=\"list\">\n<a name=\"more\"\/><\/p>\n<li class=\"td-item\"> <span aria-hidden=\"true\" class=\"td-dot\"\/>\n<div class=\"td-stack\"> <span class=\"td-punch\">Fake IT, Real Access<\/span>  <\/p>\n<p class=\"td-desc\"> Microsoft has warned of a human-operated intrusion campaign that leverages Microsoft Teams external collaboration to impersonate IT or help desk personnel and socially engineer users into granting an interactive remote session. \u00abOnce remote control is established via RMM tools, the threat actor uses PowerShell to download and silently install a malicious MSI package, which in turn stages a portable Node.js runtime and an obfuscated JavaScript implant that provides persistent command execution and command and control (C2),\u00bb the tech giant <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/09\/02\/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access\/\" target=\"_blank\">said<\/a>. \u00abAfter the implant is deployed, the threat actor performs extensive host and Active Directory reconnaissance, periodically captures screenshots of the victim\u2019s desktop, executes follow-on payloads through trusted Windows binaries, and pivots across the enterprise over Windows Remote Management (WinRM) toward high-value assets such as domain controllers.\u00bb Microsoft has described the \u00abintrusion pattern\u00bb as high-impact as it grants an external operator interactive access to internal infrastructure. <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Teams Vishing at Scale<\/span><\/p>\n<p class=\"td-desc\">\n      In more Teams-related abuse, a coordinated social engineering operation dubbed Spring Ring has been observed leveraging external Microsoft Teams accounts to masquerade as IT help desk personnel to target more than 150 employees across at least 10 companies in various industries between January and April 2026. \u00abWhat seems like a benign chat is in fact a voice phishing (vishing) call, during which adversaries try to coerce victims into executing remote monitoring and management (RMM) tools or custom malware,\u00bb Palo Alto Networks Unit 42 <a href=\"https:\/\/unit42.paloaltonetworks.com\/spring-ring-voice-phishing-campaigns\/\" target=\"_blank\">said<\/a>. \u00abIn a more advanced variant, attackers transitioned from a vishing call to a full-blown Microsoft NT LAN Manager (NTLM) relay attack aimed at an organization\u2019s domain controller (DC).\u00bb As many as 26 distinct attacker identities have been identified behind the chat and call attempts.\n    <\/p>\n<\/div>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhLO4gyzDPIqQ6rAWdAvEqMms8pokCDarKt7RTui-viWghAeWD8rqNTHl_5vCxblSAM-WIKEQ_X-CbFyhqE5DEzKRMqL260E9GIVL6ySQmx0GbQiFa_u-9XhlJFhGJe0nuqot6PC3xQfSfNFizL7ImgfKhlXsRL0XIbs22PNaDbwWdVbggAKzQszPmMR2tu\/s1700-nu-rw-lo-l85-e365\/unit.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhLO4gyzDPIqQ6rAWdAvEqMms8pokCDarKt7RTui-viWghAeWD8rqNTHl_5vCxblSAM-WIKEQ_X-CbFyhqE5DEzKRMqL260E9GIVL6ySQmx0GbQiFa_u-9XhlJFhGJe0nuqot6PC3xQfSfNFizL7ImgfKhlXsRL0XIbs22PNaDbwWdVbggAKzQszPmMR2tu\/s1700-nu-rw-lo-l85-e365\/unit.png\" alt=\"\" border=\"0\" data-original-height=\"958\" data-original-width=\"686\"\/><\/a><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Ransomware Affiliate Playbook<\/span><\/p>\n<p class=\"td-desc\">\n      In a new report, Sophos revealed that The Gentlemen ransomware operation, which it tracks as Gold Sherwood, has claimed a total of 683 victims by the end of July 2026. In July alone, the group is said to have added 169 victims. \u00abThe Gentlemen ransomware intrusions [\u2026] demonstrate a repeatable affiliate playbook that combines opportunistic initial access, rapid privilege escalation, legitimate remote access mechanisms, tool staging in trusted system paths, targeted data exfiltration, aggressive defense evasion, backup disruption, and ransomware deployment,\u00bb Sophos <a href=\"https:\/\/www.sophos.com\/en-gb\/blog\/ungentlemanly-behavior-insights-into-a-ransomware-operation\" target=\"_blank\">said<\/a>. \u00abAffiliates are operationally flexible: they use native Windows utilities, commercial and open-source tools, BYOVD-based EDR killers, and backup service tampering to adapt to victims\u2019 environments and maximize impact before encryption.\u00bb\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">PhaaS Survives Takedown<\/span><\/p>\n<p class=\"td-desc\">\n      The Outsider phishing-as-a-service (PaaS) platform has continued to be a resilient threat in the face of law enforcement action that took down a number of domains related to the service. The kit is operated by a threat actor known as \u00abChenLun.\u00bb Group-IB <a href=\"https:\/\/www.group-ib.com\/blog\/chenlun-outsider-phaas-kit\/\" target=\"_blank\">said<\/a> it has identified over 700 new phishing pages created using the kit within a month after Google filed a civil lawsuit against its operators, indicating that affiliates are continuing to use the service. The campaigns are delivered via SMS. \u00abWhat was once a technically demanding operation has been reduced to a subscription and a Telegram channel,\u00bb Group-IB said. \u00abThe phishing kits are distributed via a dedicated Telegram ecosystem. Operators used a WebSocket connection for live keylogging and to manipulate MFA challenges.\u00bb\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Signed Software, Hidden Payload<\/span><\/p>\n<p class=\"td-desc\">\n      A government-themed tax notice campaign is targeting recipients through U.A.E.- and India-themed tax assessment lures to persuade them to open a malicious disc image. \u00abThe disc image contains a legitimate, validly signed commercial executable alongside a hidden, unsigned malicious DLL,\u00bb iZOOlogic <a href=\"https:\/\/izoologic.com\/threat-advisory\/threat-analysis-report-government-themed-tax-campaign-abuses-signed-software-for-dll-side-loading-and-fileless-execution\/\" target=\"_blank\">said<\/a>. \u00abThis makes abuse of software trust and DLL sideloading the central mechanism of the campaign. The malicious DLL acts as a loader and establishes multiple execution and persistence mechanisms. The loader contains three encrypted payloads. Two decrypt to legitimately signed kernel drivers from unrelated commercial products, while the third is a persistence script.\u00bb The attack chain paves the way for a Registry-resident second stage, which connects to an external server over UDP.\n    <\/p>\n<\/div>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhW4kKYAE11z_iATVO4F4HAptdM7YfxUCByPD6ZZWiJ76CrE-SyUxIGQh88D0iLs3IJPzbEZcQjAlLR0jXFOlQjz52-dmtaY0BMuNTDKTYjDrHdUX0r6CYcThnN27Juv9WpRbXPEZ84WIPuFScKHq7IX6VP7btFaZC_GUPnjP-MDUJsOUQn1WCMZr7aMwDT\/s1700-nu-rw-lo-l85-e365\/zoo.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhW4kKYAE11z_iATVO4F4HAptdM7YfxUCByPD6ZZWiJ76CrE-SyUxIGQh88D0iLs3IJPzbEZcQjAlLR0jXFOlQjz52-dmtaY0BMuNTDKTYjDrHdUX0r6CYcThnN27Juv9WpRbXPEZ84WIPuFScKHq7IX6VP7btFaZC_GUPnjP-MDUJsOUQn1WCMZr7aMwDT\/s1700-nu-rw-lo-l85-e365\/zoo.png\" alt=\"\" border=\"0\" data-original-height=\"732\" data-original-width=\"813\"\/><\/a><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Executive Phishing as a Service<\/span><\/p>\n<p class=\"td-desc\">\n      ZeroBEC has disclosed details of a turnkey phishing service called BlueKit that\u2019s being used to target CEOs of financial-industry groups to facilitate credential theft using a browser-in-the-middle (<a href=\"https:\/\/www.netcraft.com\/blog\/bluekit-phishing-as-a-service-threat\" target=\"_blank\">BitM<\/a>) infrastructure. The campaign uses document-sharing lures to trigger the attack chain and employs ZeroBot to screen bots. \u00abThe campaign did not stop at credential or session theft,\u00bb ZeroBEC <a href=\"https:\/\/zerobec.com\/blog\/bluekit-phaas-browser-in-the-middle-screenconnect\" target=\"_blank\">said<\/a>. \u00abAfter a BlueKit browser-in-the-middle flow, selected victims were moved into a fake document-viewer workflow that delivered a legitimate ScreenConnect client configured for an attacker-used ScreenConnect cloud instance.\u00bb The service advertises access at $250 for seven days, $480 for 14 days, and $940 for 30 days, placing it at the higher end of the current PhaaS market, in comparison to Tycoon 2FA, Greatness, and Forg365, which cost approximately $350, $289, and $400 per month.\n    <\/p>\n<\/div>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhaSMXB1n34VmNPBxoURiZNPU_wpAjX96o4QACnbYspcYvTYqmWwtNxTPKzKJvJ3oaoHZ1fbcK6xOLuorz0w2i3IE4nYlOfDGOtUOBtR-8wS2u8zeYInnqxBKnbxcFXmlnjLt4XtUlKGjOwjv6CStNfDIcOY-v-dgwpbDNCsKW3cOkie6BUAjBMzs0TTo3F\/s1700-nu-rw-lo-l85-e365\/blue.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhaSMXB1n34VmNPBxoURiZNPU_wpAjX96o4QACnbYspcYvTYqmWwtNxTPKzKJvJ3oaoHZ1fbcK6xOLuorz0w2i3IE4nYlOfDGOtUOBtR-8wS2u8zeYInnqxBKnbxcFXmlnjLt4XtUlKGjOwjv6CStNfDIcOY-v-dgwpbDNCsKW3cOkie6BUAjBMzs0TTo3F\/s1700-nu-rw-lo-l85-e365\/blue.jpg\" alt=\"\" border=\"0\" data-original-height=\"941\" data-original-width=\"1672\"\/><\/a><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Dormant Domains, Ready C2<\/span><\/p>\n<p class=\"td-desc\">\n      Cybersecurity researchers have analyzed the infrastructure powering the operations of Prince of Persia (aka Indy), a little-known Iranian hacking group known for deploying malware families, Foudre and Tonnerre, to profile victims and harvest sensitive data from high-value targets. According to <a href=\"https:\/\/www.whisper.security\/resources\/blog\/prince-of-persia-mapping-the-backend-and-a-reserve-of-domains-staged-for-what-comes-next\" target=\"_blank\">Whisper Security\u2019s Kaveh Azarhoosh<\/a>, the backend is self-authoritative, with each live C2 server also running the nameservers for its own domains. Also identified is a dormant reserve of 58 domains that are registered and delegated to the group\u2019s own nameservers, but none of which currently points at any server. \u00abThey\u2019re staged, not live: the moment any one of them gains an address record, a new command server has gone live \u2014 and it\u2019s visible before the server does anything at all,\u00bb Azarhoosh told The Hacker News via email.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Remote-Controlled Rubber Ducky<\/span><\/p>\n<p class=\"td-desc\">\n      Intezer has <a href=\"https:\/\/research.intezer.com\/blog\/2026\/09\/rubber-ducky-in-the-sky\/\" target=\"_blank\">detailed<\/a> a fake \u00abprivacy browser\u00bb downloaded from a counterfeit site (\u00abwww.mxsetuplogi.com\u00bb) that turns remote attacker commands into simulated mouse and keyboard input on a victim\u2019s machine. The site is surfaced via a sponsored search result on Google, in this case after the victim mistyped the domain name (\u00abwww.mxsetup.logi.con\u00bb) on the address bar. The cybersecurity company described it as a <a href=\"https:\/\/www.threatlocker.com\/blog\/beware-the-rubber-duckies\" target=\"_blank\">USB Rubber Ducky attack<\/a> delivered over the internet. \u00abThis attack evades EDR and sits at zero to two detections on VirusTotal,\u00bb it said in a statement. \u00abThe infection began with one simple mistyped letter during routine mouse setup that routed the victim through a malvertising network into an MSIX installer signed through Microsoft\u2019s own infrastructure.\u00bb The campaign has been tracked back to a <a href=\"https:\/\/www.virustotal.com\/gui\/file\/c41e9559f18a18c058e38014f6c68b1c7953374db5b26ddee0b7700c82fbebcb\" target=\"_blank\">similar operation<\/a> from January 2016, indicating that the activity has been active for at least a decade.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">153 Million IDs for Sale<\/span><\/p>\n<p class=\"td-desc\">\n      The U.S. Federal Bureau of Investigation (FBI) is investigating a new ID theft service called Nexus, which claims to have digital scans of over 153 million driver\u2019s licenses from people in the U.S. and Canada. According to independent security journalist <a href=\"https:\/\/krebsonsecurity.com\/2026\/09\/fbi-probes-service-selling-153m-drivers-licenses\/\" target=\"_blank\">Brian Krebs<\/a>, the service is said to be siphoning images collected by a widely used identity verification company called IDScan.net based in Louisiana. The service, launched on the dark web on August 31, 2026, also boasts of more than 10 million identification cards, more than three million travel documents and\/or international IDs, and at least 579,000 medical cards. Each record can be unlocked for $100. Shortly after the expos\u00e9 was published, Nexus went offline. IDscan.net is said to be investigating the incident on its end.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">AI Instructions Become a Trap<\/span><\/p>\n<p class=\"td-desc\">\n      A scan of 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies has uncovered <a href=\"https:\/\/llmstxt.org\/\" target=\"_blank\">llms.txt or llms-full.txt<\/a> that are being placed at the root of their websites, alongside robots.txt. \u00abThe file is not a sitemap and it is not a disclaimer,\u00bb an Israeli stealth startup said. \u00abIt is a curated instruction set for AI agents: what to read, which APIs to call, which packages to install, which domains to trust. OpenAI, Anthropic, and Google publish their own.\u00bb Of the <a href=\"https:\/\/whatwouldai.do\/\" target=\"_blank\">8,265 llms.txt and llms-full.txt files<\/a> surfaced from the scan, 120 of them, each on a different site, featured install instructions pointing to PyPI or npm package names and domains that had never been registered. \u00abWe selected a small set of package names that appeared in the llms.txt files of companies you have definitely heard of, and registered them on PyPI and npm,\u00bb Alon Hertz, one of the researchers <a href=\"https:\/\/medium.com\/@alonhertz1\/data-became-code-we-ran-code-inside-fortune-500s-using-files-they-published-for-ai-agents-0cd67ffbbffc\" target=\"_blank\">said<\/a>. \u00abInto each one we embedded a single phone-home \u2014 a minimal beacon that reported the fact of installation back to infrastructure we controlled. The first callback arrived in under four minutes.\u00bb What\u2019s troubling here is that at least one active attack has already exploited this misconfiguration, in which authentication vendor Clerk\u2019s llms.txt included a reference to an npm package named \u00abclerk-next-fix-auth-protection\u00bb instead of referencing its scoped package, @clerk\/eslint-plugin. An unknown threat actor registered a public package with the same name. The package contained code to transmit the installer\u2019s username, machine name, working directory, and timestamp to an external server. Clerk has since addressed the issue.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">AI Defenders Sound the Alarm<\/span><\/p>\n<p class=\"td-desc\">\n      A coalition of over 100 companies, including Anthropic, Google, OpenAI, Microsoft, Perplexity, and others, has published an open-leet calling for improvements to cybersecurity as AI continues to compress compress cyberattack timelines, as well as accelerate the speed and scale of cyber attacks, leaving defenders with an ever-shortening window to address security issues before they are exploited. The signatories noted that current approaches to cybersecurity are not equipped to deal with the incoming surge in AI-enabled attacks, and that threat actors can rely on AI tools to target longstanding vulnerabilities, excessive permissions, misconfigurations, insecure and unpatched software, weak authentication, and technical debt in legacy systems. \u00abIn the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable,\u00bb the letter <a href=\"https:\/\/openai.com\/collective-cyberdefense\/\" target=\"_blank\">warns<\/a>. \u00abThe companies and public services our communities depend on \u2013 from hospitals to water treatment plants to the infrastructure that powers the internet \u2013 are at risk. Today\u2019s AI advances are already giving defenders new ways to fix weaknesses that have accumulated for years. If we act decisively, we can use the defenders\u2019 window to make our digital world much more secure.\u00bb\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Legacy Login Exposes 5K Accounts<\/span><\/p>\n<p class=\"td-desc\">\n      Dropbox has disclosed that about 5,000 accounts were compromised last month, allowing threat actors to view and download content stored on the cloud-storage \u200c platform. The company <a href=\"https:\/\/www.reuters.com\/technology\/dropbox-says-about-5000-accounts-compromised-august-hack-2026-09-02\/\" target=\"_blank\">told<\/a> Reuters that it \u00abidentified unauthorized access \u200baffecting accounts linked to a Lenovo ID \u200bthat did not have its two-factor authentication enabled,\u00bb adding it terminated all sessions authenticated through a Lenovo ID. Lenovo said the issue is related to a \u00ablegacy \u2060integration\u00bb between Lenovo ID and Dropbox that \u00abcould be used to improperly authenticate certain Dropbox accounts.\u00bb\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Kernel Protection by Default<\/span><\/p>\n<p class=\"td-desc\">\n      Microsoft has <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/windows-itpro-blog\/expanding-memory-integrity-protection-across-windows-devices\/4551984\" target=\"_blank\">announced<\/a> that it will expand memory integrity protection across eligible devices starting October 2026, to help users benefit from \u00abstronger kernel-level protection from sophisticated attacks by default with little or no additional configuration.\u00bb The company continued: \u00abThis change reduces security complexity while helping you establish a stronger security baseline across your environment. Built on Virtualization-based Security (VBS), memory integrity helps protect critical parts of Windows from tampering. It forms a foundation for modern security innovations such as hotpatch updates that improve user experience and productivity, as well as protection.\u00bb\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Pro-Ukraine Ransomware Rebrand<\/span><\/p>\n<p class=\"td-desc\">\n      A new ransomware group named <a href=\"https:\/\/www.f6.ru\/blog\/vantacore\/\" target=\"_blank\">VantaCore<\/a> has targeted at least seven Russian companies with a proprietary ransomware strain and demanding millions of dollars in ransom. The threat actor is assessed to be a rebranding of a known pro-Ukrainian group tracked as Thor, F6 said. Also put to use in the attacks are VantaCoreLoader, to distribute the ransomware and other malicious programs, VantaCoreRAT, a backdoor that can harvest information about infected systems and execute commands, and SnowKiller, which can terminate security software using the BYOVD technique.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Sextortion Suspects Face Life<\/span><\/p>\n<p class=\"td-desc\">\n      Two Nigerian nationals, Adebola Festus Adekunle, 26, and Mudasiru Afeez Olawale, 24, have been <a href=\"https:\/\/www.justice.gov\/opa\/pr\/two-nigerian-nationals-extradited-nigeria-united-states-face-sextortion-charges-north\" target=\"_blank\">extradited<\/a> to the U.S. to face prosecution in two separate cases for the financially-motivated sextortion of minors that led to the death of minors in both the Northern District of Mississippi and the Middle District of North Carolina. Both of them face a maximum penalty of life in prison and mandatory minimum prison sentences, with the child exploitation resulting in death charge carrying a minimum penalty of 30 years in prison.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Hardware-Backed Digital IDs<\/span><\/p>\n<p class=\"td-desc\">\n      Google <a href=\"https:\/\/blog.google\/security\/android-strongbox-and-open-standards-digital-credentials\/\" target=\"_blank\">said<\/a> it\u2019s expanding the Android Ready SE initiative to bring together silicon vendors, device manufacturers, wallet developers, and government issuers to streamline compliance and scale certified hardware security across the mobile ecosystem. The development is seen as a way to scale high-assurance, tamper-resistant digital identity amid accelerating global demand for securely storing national electronic IDs (eIDs) and mobile driver licenses (mDLs) in hardware-backed mobile wallets.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">OAuth Access Outlives Passwords<\/span><\/p>\n<p class=\"td-desc\">\n      The FBI has warned that malicious cyber actors have been targeting prominent victims, their family members, and personal acquaintances by directly messaging personal accounts with malicious links leveraging a technique called OAuth consent phishing to gain access to their accounts. The activity has targeted government officials, media, and other publicly known personalities on a commercial messaging application (CMA), urging them to access a malicious link under the guise of a file-sharing service through an application under the malicious actor\u2019s control. \u00abPrevious phishing campaigns have also impersonated event coordinators and planners, who sent malicious links to targets under the guise of an invitation to an event and the need to verify the target\u2019s identity through a malicious application under the actor\u2019s control,\u00bb the FBI <a href=\"https:\/\/www.ic3.gov\/PSA\/2026\/PSA260901\" target=\"_blank\">said<\/a>. Authorities did not provide any details about how many people may have been compromised by these attacks, or who is behind them.\n    <\/p>\n<\/div>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhF5ElQ0IF6e0hCJEqqZMC6Zp4myC79iRhBNeA2xirM1A3BXlzGyRlPL4QGJ17PNlVNV_bCUapNNTOhOb53yw_9WvBshnWWY_hIeGa5hNco9Vq5ljgBuma2-3c3JQpag8wJL40SSXmd_o6jaeMXayCxZmNwpRkGlK1KPSNf-p3b8ceDTJbs6LgAYuYRv1H8\/s1700-nu-rw-lo-l85-e365\/oauth.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhF5ElQ0IF6e0hCJEqqZMC6Zp4myC79iRhBNeA2xirM1A3BXlzGyRlPL4QGJ17PNlVNV_bCUapNNTOhOb53yw_9WvBshnWWY_hIeGa5hNco9Vq5ljgBuma2-3c3JQpag8wJL40SSXmd_o6jaeMXayCxZmNwpRkGlK1KPSNf-p3b8ceDTJbs6LgAYuYRv1H8\/s1700-nu-rw-lo-l85-e365\/oauth.png\" alt=\"\" border=\"0\" data-original-height=\"1733\" data-original-width=\"1371\"\/><\/a><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Electron Apps Hide a Stealer<\/span><\/p>\n<p class=\"td-desc\">\n      Trojanized Electron desktop applications impersonating legitimate software are being used to distribute a Windows information stealer called RevStealer. The applications are shared via GitHub repositories and game-cheat-themed sites, including a fake Claude Opus 5 Free Desktop project. \u00abIt is delivered by an Electron loader that hides an AES-encrypted native payload inside an application resource, attempts to add the user\u2019s AppData folder to Microsoft Defender\u2019s exclusion list, and launches the payload with no visible window,\u00bb Morphisec <a href=\"https:\/\/www.morphisec.com\/blog\/revstealer-silence-is-its-greatest-weapon\/\" target=\"_blank\">said<\/a>. The malware also runs a series of anti-analysis and anti-VM checks before unpacking the main payload. \u00abIf the primary C2 is unreachable, RevStealer reads a fallback address from a smart contract on the Polygon blockchain, letting operators rotate infrastructure without rebuilding the malware,\u00bb the company said. What\u2019s notable about the malware is that it\u2019s not designed for persistence. Rather, it prioritizes capturing as much data as possible in a single run, exfiltrates it in encrypted typed records, and then deletes itself.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Trusted Tool, Rogue Access<\/span><\/p>\n<p class=\"td-desc\">\n      Threat actors are weaponizing Faronics Deploy, a legitimate endpoint management platform, to run attacker-controlled PowerShell after phishing victims install the software. Huntress said it observed more than 457 endpoints encountering Faronics-related lures. \u00abIn observed cases, threat actors chained Faronics Deploy to ScreenConnect, blending malicious remote access activity into trusted software workflows,\u00bb it <a href=\"https:\/\/www.huntress.com\/blog\/faronics-deploy-abuse\" target=\"_blank\">said<\/a>. \u00abThe delivery method varies between scripts, with observed examples using curl or MSHTA to retrieve additional content, while others invoke msiexec to install payloads hosted on attacker-controlled infrastructure. These scripts are subsequently used to install ScreenConnect, establishing an additional remote access mechanism on the compromised endpoint.\u00bb\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">ClickFix Goes Cross-Platform<\/span><\/p>\n<p class=\"td-desc\">\n      Cybersecurity researchers have described CRPx0 as a ClickFix-delivered ransomware-as-a-service (RaaS) operation that employs lures related to Windows and macOS update prompts and reCAPTCHA checks to trick victims into running a copied command. \u00abOn Windows, it starts a multi-stage DLL chain. On macOS, it downloads the Python payload directly,\u00bb the Ransom-ISAC Research Team <a href=\"https:\/\/ransom-isac.org\/blog\/crpx0-clickfix-ransomware-analysis\/\" target=\"_blank\">said<\/a>. \u00abThe final payload is a cross-platform Python ransomware that exfiltrates data before encryption, encrypts files with AES-128-CBC via Fernet, wraps the per-victim key with an embedded RSA-4096 public key, attempts lateral movement, and drops ransom notes demanding Bitcoin or Monero payment within 48 hours.\u00bb The RaaS program first appeared on June 7, 2026. As of late August, the group has advertised the operation on a clearnet site (\u00abcrpx0[.]su\/v3.txt\u00bb) as an offensive control panel to manage compromised machines, harvest files and credentials, monitor stolen cryptocurrency artifacts, run remote commands, and launch ransomware manually.\n    <\/p>\n<\/div>\n<\/li>\n<\/ol>\n<\/section>\n<\/div>\n<p>One point is easy to miss: changing a password may not shut every door. A bad app approval or remote session can give attackers access without the password. Recovery should also end open sessions, remove unknown app access, and check remote tools.<\/p>\n<p>Better security settings are slowly becoming the default, which helps. But old account links, weak sign-in options, and trusted software still give attackers room to work. The safest rule this week is simple: check what already has access before adding anything new.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click \u201cAllow.\u201d Why break in when someone might open the door? That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides that point [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1901,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25,5],"tags":[2969,4212,24,4213,2206,1317,360,365,23,19],"class_list":["post-1900","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-noticias","category-trending","tag-account","tag-ceo","tag-cyberdefensa-mx","tag-dropbox","tag-hacks","tag-kits","tag-oauth","tag-phishing","tag-stories","tag-traps"],"_links":{"self":[{"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/posts\/1900","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/comments?post=1900"}],"version-history":[{"count":0,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/posts\/1900\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/media\/1901"}],"wp:attachment":[{"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/media?parent=1900"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/categories?post=1900"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/tags?post=1900"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}